4 ms·
I'm only just learning about all this stuff so might be a somewhat naive question, but if we created some kind of operating system like plan9 that was coded in
by rcarr 3y ago
I'm only just learning about all this stuff so might be a somewhat naive question, but if we created some kind of operating system like plan9 that was coded in rust or another similar language, that offered compatibility for existing linux software, and then moved towards creating all new software in memory safe languages would this solve not only this problem but a lot of other problems also? I read today that containers and container management wouldn't need to be half as complex as they are today if plan9 had taken off the same way linux did. Would be a big, big effort but if a major player got behind it like AWS then maybe not impossible. Redox looks like an interesting attempt at creating something like this.
https://www.redox-os.org/ https://www.redox-os.org/
https://drewdevault.com/2022/11/12/In-praise-of-Plan-9.html https://drewdevault.com/2022/11/12/In-praise-of-Plan-9.html
https://news.ycombinator.com/item?id=26554539 https://news.ycombinator.com/item?id=26554539
- layer8 3y agoThere is little incentive for the major players to invest in such a hugely expensive effort. Furthermore, a lot of software is running on non-Linux systems.
- rcarr 3y agoIn my head, the incentive would be companies could save the time and effort that they're investing in Docker/K8s as well as getting better security because of the memory safety. Would that not be enough to warrant the shift, at least for software that is running on Linux systems? Feels like you could get rid of a lot of the Docker/K8s overhead which could translate into lower operating costs as well.
- eximius 3y ago"rewrite everything correctly" does more or less solve the issue by definition but it is very hard for so many reasons. Which isn't to say we can't take some learnings from the idea, just that it isn't simply a matter of money.
- ActorNightly 3y agoAll that is needed to prevent remote exploits from taking effect is strong input/output sanitization, and firewall. It becomes next to impossible to exploit vulnerable software if you are limited to the characters you can send. Most web services do this in the network level with load balancers that forward only a single port to the service VM that is otherwise behind NAT to prevent any access to any other program in the VM that is left listening on a port. You can extend this concept to the input and output processing of the service.
- rtev 3y agoi don’t feel that this is true in the slightest. so many critical exploits use the same characters and lengths as intended inputs. Also, if firewalls were a replacement for secure code, no one would be talking about memory safety.
- ActorNightly 3y agoNo. In order to exploit modern memory corruptions, you have to most often send a shitload of data with significant lengths to fill up memory strategically and/or rop gadget jump addresses. None of this looks like real payloads. https://github.com/stong/how-to-exploit-a-double-free https://github.com/stong/how-to-exploit-a-double-free The analogy to firewalls is that you would specify the exact condition of the input for it to forward to the actual program. For example, if your endpoint receives json, you would validate the json and check each field value for valid range, ie min max number of characters and what those character values could be for each field. Just like a firewall limits who can talk to who in way.